nerdexam
EC-Council

312-50V9 · Question #438

A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before…

The correct answer is B. Determine the impact of enabling the audit feature. Before enabling a new security feature on a production system, the organization must first assess the potential impact that feature will have on system performance and operations.

Introduction to Ethical Hacking

Question

A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?

Options

  • APerform a vulnerability scan of the system.
  • BDetermine the impact of enabling the audit feature.
  • CPerform a cost/benefit analysis of the audit feature.
  • DAllocate funds for staffing of audit log review.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    87% (45)
  • C
    8% (4)
  • D
    4% (2)

Why each option

Before enabling a new security feature on a production system, the organization must first assess the potential impact that feature will have on system performance and operations.

APerform a vulnerability scan of the system.

A vulnerability scan assesses existing security weaknesses in the system and is unrelated to the planning needed before enabling an audit feature.

BDetermine the impact of enabling the audit feature.Correct

Enabling auditing on a live production system can affect performance, storage capacity, and availability, so determining the impact is the essential first step before any implementation. This analysis identifies whether the system can handle the additional overhead and what configuration choices are required to prevent unintended outages or data integrity issues. Only after understanding the impact can the organization make informed decisions about cost, staffing, and implementation approach.

CPerform a cost/benefit analysis of the audit feature.

A cost/benefit analysis is a valid later step, but it depends on knowing the impact first - you cannot calculate cost or benefit without understanding what enabling the feature does to the system.

DAllocate funds for staffing of audit log review.

Allocating funds for audit log review is an operational step that follows the impact and cost analysis, not the first action to take.

Concept tested: Impact assessment before enabling audit controls

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#impact analysis#audit controls#risk management#security policy

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice